
apache-web-log-analysis-lab
Blue Team lab focused on analyzing Apache web access logs to detect directory brute forcing and web scanning activity.

Blue Team lab focused on analyzing Apache web access logs to detect directory brute forcing and web scanning activity.

Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic…

CVE-2021-41773 playground

Vulnerability as a service: showcasing CVS-2015-5447, a DDoS condition in the bind9 software

CVE-2022-0543 - Redis RCE Vulnerability home lab for Red Teaming, Penetration Testing Training with just one DOCKER

An Ansible Role that installs the xz backdoor (CVE-2024-3094) on a Debian host and optionally installs the xzbot tool.

Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock

Vulnerability as a service: showcasing CVS-2014-0160, a.k.a. Heartbleed

Exploitation of CVE-2023-44604. Using a Kali Linux VM (attacker) and a Debian 11 server VM (victim)

Apache HTTPd (2.4.49) – Local File Disclosure (LFI)